PCNSE Securing Traffic and App-ID Practice Question
A security administrator is configuring an outbound security policy for a new SaaS application. The application uses multiple dynamic ports and occasionally changes its server IPs. The administrator wants to allow only this application while blocking all other traffic on those ports. Which Palo Alto Networks feature should be used to identify and control this application?
⚠ Common exam trap
The trap here is assuming that a port-based service object or IP-based EDL can reliably control an application that uses dynamic ports and changing IPs, but only App-ID can identify the application regardless of those factors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App-ID with application filters in the security policy
App-ID with application filters allows the firewall to identify the SaaS application by its unique traffic characteristics, not by port or IP. This ensures that only the desired application is allowed, even when it uses dynamic ports or changes IP addresses. Application filters further refine policy by grouping applications based on attributes like category and risk, providing granular control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service objects with TCP port ranges in the security policy
Why it's wrong here
Service objects define port ranges, but the application uses dynamic ports, so a static port range would not reliably match. Additionally, other applications could use the same ports, leading to incorrect allow. Service objects do not provide application-level visibility or control, which is required to distinguish the SaaS application from other traffic.
- ✓
App-ID with application filters in the security policy
Why this is correct
App-ID identifies the application regardless of port or IP, and application filters allow grouping applications by characteristics such as category, subcategory, technology, and risk. This enables precise control over the SaaS application while blocking others, even with dynamic ports and changing IPs. App-ID is the core technology for application-based policy enforcement on Palo Alto Networks firewalls.
- ✗
External Dynamic Lists (EDLs) with IP addresses of the SaaS provider
Why it's wrong here
EDLs are used to dynamically import IP addresses or domains for policy matching. However, the SaaS application changes server IPs frequently, making IP-based control unreliable. Moreover, EDLs do not identify the application itself, so other applications hosted on the same IPs could be inadvertently allowed, violating the requirement to block all other traffic.
- ✗
URL filtering profiles with custom URL categories
Why it's wrong here
URL filtering operates at the HTTP/HTTPS layer and classifies based on URLs, not application behavior. The SaaS application may use non-web protocols or encrypted traffic that URL filtering cannot accurately identify. This approach would not reliably control the application, especially if it uses dynamic ports and non-standard protocols.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.